[sr-dev] [kamailio/kamailio] Kamailio crashes with debug level > 2 and registering from certain SIP clients (#1403)

mechanixza notifications at github.com
Wed Jan 17 22:17:43 CET 2018


<!--
Kamailio Project uses GitHub Issues only for bugs in the code or feature requests.

If you have questions about using Kamailio or related to its configuration file,
ask on sr-users mailing list:

  * http://lists.sip-router.org/cgi-bin/mailman/listinfo/sr-users

If you have questions about developing extensions to Kamailio or its existing
C code, ask on sr-dev mailing list

  * http://lists.sip-router.org/cgi-bin/mailman/listinfo/sr-dev

Please try to fill this template as much as possible for any issue. It helps the
developers to troubleshoot the issue.

If you submit a feature request (or enhancement), you can delete the text of
the template and only add the description of what you would like to be added.

If there is no content to be filled in a section, the entire section can be removed.

You can delete the comments from the template sections when filling.

You can delete next line and everything above before submitting (it is a comment).
-->

### Description

<!--
Explain what you did, what you expected to happen, and what actually happened.
-->
When registering a soft client running on my Android phone (Grandstream Wave), Kamailio crashes every time when the client registers. When setting the debug level below 3 Kamailio does not crash. I have only found the problem with this SIP client. Others are working fine.

### Troubleshooting

#### Reproduction

<!--
If the issue can be reproduced, describe how it can be done.
-->
Set debug level greather than 2 and register the Grandstream Wave soft client from an Android phone. Kamailio then crashes.

#### Log Messages

<!--
Check the syslog file and if there are relevant log messages printed by Kamailio, add them next, or attach to issue, or provide a link to download them (e.g., to a pastebin site).
-->

just before crashing I get the following message:
0(7819) ERROR: <core> [core/udp_server.c:484]: udp_rcv_loop(): print buffer building failed (10/16/4)

### Possible Solutions

<!--
If you found a solution or workaround for the issue, describe it. Ideally, provide a pull request with a fix.
-->
The problem seems to come from non-printable characters sent by the SIP client causing Kamailio to crash. 

Changing line 482 in udp_server.c from
l = snprintf(printbuf+j, 6, " %02X ", buf[i]);
to
l = snprintf(printbuf+j, 6, " %02X ", (unsigned char)buf[i]);

fixes the problem.

The compiler treats buf[i] as a signed integer and prepends 'FFFFFF' to the string making it longer than 6 characters. Casting buf[i] as an unsigned char prevents Kamailio from crashing.

### Additional Information

  * **Kamailio Version** - output of `kamailio -v`

version: kamailio 5.1.0 (x86_64/linux) 
flags: STATS: Off, USE_TCP, USE_TLS, USE_SCTP, TLS_HOOKS, DISABLE_NAGLE, USE_MCAST, DNS_IP_HACK, SHM_MEM, SHM_MMAP, PKG_MALLOC, Q_MALLOC, F_MALLOC, TLSF_MALLOC, DBG_SR_MEMORY, USE_FUTEX, FAST_LOCK-ADAPTIVE_WAIT, USE_DNS_CACHE, USE_DNS_FAILOVER, USE_NAPTR, USE_DST_BLACKLIST, HAVE_RESOLV_RES
ADAPTIVE_WAIT_LOOPS=1024, MAX_RECV_BUFFER_SIZE 262144, MAX_LISTEN 16, MAX_URI_SIZE 1024, BUF_SIZE 65535, DEFAULT PKG_SIZE 8MB
poll method support: poll, epoll_lt, epoll_et, sigio_rt, select.
id: unknown 
compiled with gcc 5.3.1


* **Operating System**:

<!--
Details about the operating system, the type: Linux (e.g.,: Debian 8.4, Ubuntu 16.04, CentOS 7.1, ...), MacOS, xBSD, Solaris, ...;
Kernel details (output of `uname -a`)
-->

Ubuntu 16.04 (Xenial)


-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/kamailio/kamailio/issues/1403
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.kamailio.org/pipermail/sr-dev/attachments/20180117/3e503911/attachment-0001.html>


More information about the sr-dev mailing list